CVE-2026-90808

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.3
MEDIUM
CVSS v2 Base Score
6.5
MEDIUM

Description

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name: af582246f141311d574551b7571a517bcc3df750. Applying a patch is the recommended action to fix this issue.

Published
September 14, 2026 7:18 PM
Last Modified
September 14, 2026 7:18 PM
Source
[email protected]

Weaknesses (CWE)

CWE-183 CWE-184

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.